Why account creation doesn’t remove access-management work
See how post-provisioning entitlements affect IT capacity and audit readiness even when user creation is already automated.
Directory sync can create the account and assign baseline access. The ongoing requests for shared drives, Google Groups, Gmail delegation, third-party apps, and elevated roles still need approvals, execution, revocation, and an audit trail. See how to automate that layer end to end.
An IdP or directory sync handles the predictable part of provisioning: create the user, add standard groups, assign a licence. Once that employee starts working, access needs become more specific and more dynamic.
Requests arrive through email or chat, someone has to identify the right approver, apply policy, make the change, record what happened, and later remove temporary access. For lean IT teams, this entitlement layer can become a larger operational burden than initial provisioning.
This webinar shows how to turn those recurring requests into a controlled self-service workflow that works with Google Workspace and connected systems—without introducing a full ITSM implementation or custom Apps Script.
We’ll break down the operational gap between standard provisioning and the access changes IT still manages manually, then build the workflow that closes it.
See how post-provisioning entitlements affect IT capacity and audit readiness even when user creation is already automated.
Connect standard IdP or GCDS provisioning with the day-to-day requests that otherwise continue to land with IT manually.
Follow conditional routing, approval gates, automated provisioning, and complete audit logging in one live workflow.
Add expiry and review controls so permissions don’t accumulate into an offboarding burden or an audit liability.
See the pattern behind common access automations that reduced IT tickets by 83% without relying on Apps Script.
Expose the workflow conversationally while keeping its existing approval, execution, access, and audit controls intact.
Watch the request move from employee self-service to provisioning and automatic expiry, with policy and approvals applied along the way.
An employee asks for access through a self-service entry point.
The workflow resolves manager, user, role, and policy context.
Conditional logic sends the request to the right approval path.
Approved access is granted in Workspace or connected systems.
Request data, decisions, and actions are retained for audit.
Time-limited permissions are revoked automatically when due.
Gordon Food Service used this approach to automate common Google Workspace access requests and remove hours of repetitive administrative work from its IT team.
During the session, we’ll use a similar pattern to show how request intake, policy decisions, approvals, provisioning, audit logging, and time-boxed access can operate as one controlled process.
VP of Commercial, Zenphi
Pat leads commercial strategy and Customer Success at Zenphi and works closely with customers deploying workflow automation in production. Previously, he served as VP of Customer Success and Global Client Operations at Nintex, overseeing Customer Success, Professional Services, and Technical Support for 30,000 customers and 1.6 million users. He brings extensive experience helping organisations adopt, scale, and realise value from business process automation.
CEO & Head of Product, Zenphi
Vahid has more than 20 years of experience in enterprise software architecture, systems integration, and workflow automation. Before Zenphi, he spent eight years at Nintex, including nearly five years as VP of Product, where he led global product, engineering, forms, analytics, and AI initiatives. At Zenphi, he oversees the product architecture behind complex Google Workspace, IT operations, and AI-powered workflows.
See the complete workflow live, from request and approvals through provisioning, audit logging, automatic expiry, and Google Chat access.
Registration opens in a new tab.